Endpoint Security administrators and investigators can use the Trellix Endpoint Security Host Remediation module to remotely connect to endpoints and execute commands.
Use the Host Remediation module to securely connect an existing Endpoint Security server to agent endpoints using mutual TLS v1.2 and AEAD mode cipher. No additional firewall rules or ports are required for the module to be able to perform normal operations.
The Endpoint Security module requires the Trellix Endpoint Power Edition license or the Managed Defense license. It will not work on a Trellix Endpoint Essentials edition license.
The Host Remediation module is the core response component of EDRF, which provides the "Response" capability. It allows operators to take real-time corrective actions, including isolating hosts, terminating processes, deleting files, and removing persistence mechanisms. It enables administrators and investigators to establish a remote command-line session with endpoints. This provides deep, hands-on access for advanced investigation and custom remediation tasks.
For security teams, the primary benefit is a significant reduction in the Mean Time to Remediate (MTTR). The module enables immediate action upon threat detection, effectively containing threats before they escalate into widespread breaches. This centralized control reduces operational overhead by minimizing the need for manual intervention. The module transforms the Trellix EDR solution from a passive de
tection and investigation tool into an active defense system.
Important
Trellix Host Remediation Module version 2.3.x is not compatible with Endpoint Security (HX) version 11.0.1. Any versions of Host Remediation earlier than Endpoint Security (HX) version 11.0.x must be updated to module version 11.0.x after you upgrade your HX to version 11.0.1.